Regex - Spamfilter - False Positive?

These are old archives. They are kept for historic purposes only.
Post Reply
Darvocet
Posts: 105
Joined: Sun Jun 27, 2004 6:40 am
Location: Houston, TX
Contact:

Regex - Spamfilter - False Positive?

Post by Darvocet »

Recieved a complaint this morning that some DCC sends were blocked between 2 specific users. Spamfilter seems to have blocked the sends.

-nightcrow.se.eu.epicirc.net- DCC to xxUSERxx blocked: Infected by Gaggle worm
-nightcrow.se.eu.epicirc.net- *** You have been blocked from sending files, reconnect to regain permission to send files


Of course this is in the spamfilter as:

spamfilter {
regex "C:\\WINNT\\system32\\[][0-9a-z_-{|}`]+\.zip";
target dcc;
action block;
reason "Infected by Gaggle worm?";
};

Now, I am not good with regex, so sorry that I have to ask somewhat simple questions here... How could this spamfilter be blocking files. What exactially is it looking for? User test sending test.txt are blocked. User has virusscanned with updated Norton 2005, so Im just not POSITIVE that anyone is infected.

Any help is appreciated.

Darv.
- Darvocet
Sr. Network Admin: EpicIRC.Net
Dukat
Posts: 1083
Joined: Tue Mar 16, 2004 5:44 pm
Location: Switzerland

Post by Dukat »

If you don't make mistakes, you aren't really trying.
- Coleman Hawkins
Darvocet
Posts: 105
Joined: Sun Jun 27, 2004 6:40 am
Location: Houston, TX
Contact:

Post by Darvocet »

doh. thank you dukat. :)
- Darvocet
Sr. Network Admin: EpicIRC.Net
Darvocet
Posts: 105
Joined: Sun Jun 27, 2004 6:40 am
Location: Houston, TX
Contact:

Post by Darvocet »

Ok that post OBVIOUSLY is my problem but is WAY over my head. It implies that // needs to be ////. All of them?

regex "C:\\WINNT\\system32\\[][0-9a-z_-{|}`]+\.zip";

is what I show in spamfilter.conf

Does it want

regex "C:\\\\WINNT\\\\system32\\\\[][0-9a-z_-{|}`]+\.zip";
?
- Darvocet
Sr. Network Admin: EpicIRC.Net
Stealth
Head of Support
Posts: 2085
Joined: Tue Jun 15, 2004 8:50 pm
Location: Chino Hills, CA, US
Contact:

Post by Stealth »

That and the regex is entirely messed up...

What are you trying to block?
Darvocet
Posts: 105
Joined: Sun Jun 27, 2004 6:40 am
Location: Houston, TX
Contact:

Post by Darvocet »

Stealth wrote:That and the regex is entirely messed up...

What are you trying to block?
Well I wasnt trying to block anything, recieved a false positive on the 'Gaggle' entry in the spamfilter.conf. I realize that I could just remove that and make it work, but I would rather working spamfilters :)
- Darvocet
Sr. Network Admin: EpicIRC.Net
Stealth
Head of Support
Posts: 2085
Joined: Tue Jun 15, 2004 8:50 pm
Location: Chino Hills, CA, US
Contact:

Post by Stealth »

Darvocet
Posts: 105
Joined: Sun Jun 27, 2004 6:40 am
Location: Houston, TX
Contact:

Post by Darvocet »

Stealth wrote:Get the fix from CVS:
http://cvs.ircsystems.net/cgi/viewcvs.c ... l3_2_fixes
Thank you very much stealth!!!!

Have a merry christmas.

PS. I woulda just logged into the irc network for help, but DNS for irc.unrealircd.com is down. :) In case nobody notices yet.
- Darvocet
Sr. Network Admin: EpicIRC.Net
Post Reply